Splunk Search

Why am I getting no results found when creating and searching my field lookups?

sushmitha_mj
Communicator

I used this document to create my lookup table and define fields
http://docs.splunk.com/Documentation/Splunk/6.4.3/SearchTutorial/Usefieldlookups

Then I saw how to search on the document below
http://docs.splunk.com/Documentation/Splunk/6.4.3/SearchTutorial/Searchwithfieldlookups

But I get no results found. I went through the steps several times. Why would it be ?

Tags (2)
0 Karma
1 Solution

sundareshr
Legend

Start with typing |inputlookup lookupfilename to see if you get any results. If you don't its probably a permissions issue. Check permissions for lookup table AND lookup definition (global vs app vs private).

If you do get results back, Verify values in the lookup file and values in index are identical (case, spelling etc)

View solution in original post

sundareshr
Legend

Start with typing |inputlookup lookupfilename to see if you get any results. If you don't its probably a permissions issue. Check permissions for lookup table AND lookup definition (global vs app vs private).

If you do get results back, Verify values in the lookup file and values in index are identical (case, spelling etc)

aaraneta_splunk
Splunk Employee
Splunk Employee

Hello @sushmitha_mj - Without knowing any more information about your current situation, it could have something to do with your lookup table file or your sharing permissions or even the search you’re trying to perform. It would be helpful to share more information in a comment below. The more information you provide to the Answers community, the greater chance that you’ll be able to get some help. Thank you 🙂

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...